Advertisement

Bitcoin May Add Shielded Privacy Inspired by Zcash Without Changing Core Rules

Researchers have proposed a system that could enable private Bitcoin-denominated payments without changing Bitcoin’s existing protocol. However, the design does not yet provide a completed mechanism for moving actual BTC into or out of the system.

The proposal comes as privacy-focused cryptocurrencies, particularly Zcash, receive renewed attention from investors. The concept, known as Shielded Bitcoin, was published Thursday by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of cryptography firm [alloc] init.

The design draws heavily from Zcash’s approach to encrypted payments. Under the proposed system, Bitcoin-denominated funds would be represented through encrypted records called notes. When a note is spent, the user would publish a nullifier indicating that it had been used, along with a cryptographic proof demonstrating ownership of the funds and confirming that no new coins were created.

The transaction amount, sender and recipient would remain concealed.

Unlike Zcash, where the blockchain itself verifies the cryptographic proofs, Shielded Bitcoin would place the encrypted payment information on Bitcoin while relying on separate software to perform the verification. As a result, the Bitcoin network could confirm the transaction carrying the private payment even if the payment itself failed the Shielded Bitcoin checks.

The proposal arrives as privacy becomes a growing consideration for cryptocurrency applications involving payroll, corporate payments and everyday spending. Standard Bitcoin transactions permanently expose addresses and transaction amounts. Once an address can be connected to a person or company, other transactions involving that address can become easier to trace.

Ethereum developers are exploring a related concept involving a shared privacy pool. The proposed system could allow ether and other tokens to move without publicly disclosing payment information, with payroll, treasury management and donations among the potential applications.

Zcash’s Privacy Model

Zcash gives users the choice between transparent transactions, where addresses and amounts are publicly visible, and shielded transactions, which conceal those details.

CoinDesk calculations based on ZecStats data showed that Zcash’s shielded pools held about 4.9 million ZEC on Friday, up 14% from July 30. That represented roughly 29% of the cryptocurrency’s issued supply, with the holdings valued at approximately $7.8 billion following ZEC’s recent price gains.

The network processed about 63,000 shielded transactions during the previous week. That was its busiest week for private transactions since 2022 and ranked fourth-highest historically. Total reported transfer volume surpassed $23 billion, marking the largest weekly figure since 2021 and the second-highest on record.

The increased activity has coincided with a sharp rise in investor interest. ZEC had gained more than 2,300% over the previous year by early September and moved above $1,000. The token extended its rally beyond $1,600 on Wednesday.

Bitcoin’s connection to the technology behind Zcash privacy features goes back to 2013, when Zerocoin was proposed as a privacy extension for Bitcoin. Subsequent research produced Zerocash, which eventually developed into Zcash, launched as a separate cryptocurrency in 2016.

Under Shielded Bitcoin, encrypted payment data would remain on the Bitcoin blockchain. Users could use their wallet keys to reconstruct accepted private transactions from the public record. Separate viewing keys could also allow users to share transaction details with accountants or auditors without giving them the ability to spend the funds.

Deposit and Withdrawal Remain Unresolved

One of the proposal’s major open questions is how users would move ordinary BTC into the system and later withdraw it. The 56-page paper leaves those mechanisms for future research based on PIPEs, a technique designed to lock a Bitcoin signing key until predetermined conditions are satisfied.

The researchers’ claim that users maintain control over their funds applies to transfers within the proposed system and does not extend to deposits or withdrawals.

The missing mechanisms have attracted criticism from developers and Zcash supporters.

Mert Mumtaz, co-founder of Helius and a Zcash supporter, described the design on X as a synthetic ledger with notable tradeoffs. He highlighted its trusted setup requirement and the absence of fee anonymization, which could leave the Bitcoin wallet publishing a private transfer visible.

Mumtaz also questioned the lack of an in-protocol method for depositing and withdrawing actual BTC, arguing that this would mean users were dealing with synthetic assets rather than native Bitcoin.

At the same time, he acknowledged the research effort and its use of concepts developed through Zcash. He said the approach would require additional research and development before it could become a practical system.

Cypherpunk, a company that holds and mines Zcash, also welcomed the research but said it did not consider Shielded Bitcoin a direct competitor to the existing Zcash network. The company argued that privacy is most effective when implemented at the base layer, while noting that avoiding changes to Bitcoin is both a key advantage and a significant limitation of the proposal.

Cypherpunk added that greater privacy for Bitcoin could benefit the broader cryptocurrency ecosystem.

The researchers at [alloc] init also identify several limitations in their current design. Their reference system requires a cryptographic setup whose security depends on at least one participant acting honestly. Transaction timing and fee payments would remain visible, while a more efficient method for lightweight wallets to verify reconstructed payment histories remains under development.

Komarov estimates that a private transaction would require around 700 virtual bytes, compared with approximately 100 to 200 virtual bytes for a conventional Bitcoin transaction. At an equivalent fee rate, the larger transaction size would result in miner fees roughly four times higher.

As of Friday, the researchers had not provided a launch date for Shielded Bitcoin.